{"_type": "sec_certs.sample.fips.FIPSCertificate", "dgst": "622373b3957bb84f", "cert_id": 5219, "web_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.WebData", "module_name": "NITROXIII CNN35XX-NFBE HSM Family", "validation_history": [{"_type": "sec_certs.sample.fips.FIPSCertificate.ValidationHistoryEntry", "date": "2026-03-31", "validation_type": "Initial", "lab": "Leidos Accredited Testing & Evaluation (AT&E) Lab"}], "vendor_url": "http://www.jisasoftech.com ", "vendor": "JISA Softech Private Limited", "certificate_pdf_url": "https://csrc.nist.gov/CSRC/media/projects/cryptographic-module-validation-program/documents/certificates/March 2026_020426_1121-signed.pdf", "module_type": "Hardware", "standard": "FIPS 140-3", "status": "active", "level": 3, "caveat": "When operated in approved mode. When installed, initialized and configured as specified in Section 11 of the Security Policy. The module generates SSPs whose strengths are modified by available entropy", "exceptions": ["Operational environment: N/A", "Non-invasive security: N/A", "Mitigation of other attacks: N/A"], "embodiment": "MultiChipEmbed", "description": "The NITROXIII CNN35XX-NFBE HSM Family module is a high-performance purpose-built security solution for crypto acceleration. The module provides a FIPS 140-3 overall Level 3 security solution. The module is deployed inside CryptoBind HSM and CryptoBind DSS to provide crypto and TLS 1.0/1.1/1.2 acceleration in a secure manner to the system host. It is typically deployed in a CryptoBind HSM & CryptoBind DSS network appliance to provide cryptographic operations. The module\u2019s functions are accessed over the PCIe interface via an API defined by the module inside CryptoBind HSM and CryptoBind DSS.", "tested_conf": null, "hw_versions": "HW-1.0 (CNL3510-NFBE-G; CNL3510P-NFBE-G; CNL3530-NFBE-G; CNL3560-NFBE-G; CNL3560P-NFBE-G; CNN3510-NFBE-G; CNN3530-NFBE-G; CNN3560-NFBE-G; CNN3560P-NFBE-G); HW-2.0 (CNL3510-NFBE-2.0-G; CNL3510B-NFBE-2.0-G; CNL3510P-NFBE-2.0-G; CNL3510PB-NFBE-2.0-G; CNL3530-NFBE-2.0-G; CNL3530B-NFBE-2.0-G; CNL3560-NFBE-2.0-G; CNL3560B-NFBE-2.0-G; CNL3560P-NFBE-2.0-G; CNL3560PB-NFBE-2.0-G; CNN3505LP-NFBE-2.0-G; CNN3510-NFBE-2.0-G; CNN3510LP-NFBE-2.0-G; CNN3510LPB-NFBE-2.0-G; CNN3530-NFBE-2.0-G; CNN3560-NFBE-2.0-G; CNN3560P-NFBE-2.0-G); HW-3.0 (CNL3510-NFBE-3.0-G; CNL3510A-NFBE-3.0-G; CNL3510C-NFBE-3.0-G; CNL3510D-NFBE-3.0-G; CNL3510E-NFBE-3.0-G; CNL3510F-NFBE-3.0-G; CNL3510I-NFBE-3.0-G; CNL3510P-NFBE-3.0-G; CNL3530-NFBE-3.0-G; CNL3530A-NFBE-3.0-G; CNL3530B-NFBE-3.0-G; CNL3530C-NFBE-3.0-G; CNL3530D-NFBE-3.0-G; CNL3530E-NFBE-3.0-G; CNL3530F-NFBE-3.0-G; CNL3560-NFBE-3.0-G; CNL3560A-NFBE-3.0-G; CNL3560B-NFBE-3.0-G; CNL3560B-NFBE-3.0-G-FB; CNL3560C-NFBE-3.0-G; CNL3560D-NFBE-3.0-G; CNL3560E-NFBE-3.0-G; CNL3560F-NFBE-3.0-G; CNL3560P-NFBE-3.0-G; CNN3505LP-NFBE-3.0-G; CNN3505LPA-NFBE-3.0-G; CNN3505LPC-NFBE-3.0-G; CNN3505LPD-NFBE-3.0-G; CNN3505LPE-NFBE-3.0-G; CNN3505LPF-NFBE-3.0-G; CNN3510-NFBE-3.0-G; CNN3510A-NFBE-3.0-G; CNN3510C-NFBE-3.0-G; CNN3510D-NFBE-3.0-G; CNN3510E-NFBE-3.0-G; CNN3510F-NFBE-3.0-G; CNN3510LP-NFBE-3.0-G; CNN3510LPA-NFBE-3.0-G; CNN3510LPB-NFBE-3.0-G; CNN3510LPC-NFBE-3.0-G; CNN3510LPD-NFBE-3.0-G; CNN3510LPE-NFBE-3.0-G; CNN3510LPF-NFBE-3.0-G; CNN3530-NFBE-3.0-G; CNN3530A-NFBE-3.0-G; CNN3530C-NFBE-3.0-G; CNN3530D-NFBE-3.0-G; CNN3530E-NFBE-3.0-G; CNN3530F-NFBE-3.0-G; CNN3560-NFBE-3.0-G; CNN3560A-NFBE-3.0-G; CNN3560C-NFBE-3.0-G; CNN3560D-NFBE-3.0-G; CNN3560E-NFBE-3.0-G; CNN3560F-NFBE-3.0-G; CNN3560P-NFBE-3.0-G)", "fw_versions": "CNN35XX-NFBE-FW-2.09-0702, CNN35XX-NFBE-SMW-2.09-0702, CNN35XX-UBOOT-4.03-03", "sw_versions": null, "mentioned_certs": {}, "historical_reason": null, "date_sunset": "2029-05-29", "revoked_reason": null, "revoked_link": null}, "pdf_data": {"_type": "sec_certs.sample.fips.FIPSCertificate.PdfData", "keywords": {"fips_cert_id": {"Cert": {"#1": 2, "#2": 2, "#1780": 22, "#1311": 10}}, "fips_security_level": {"Level": {"Level 3": 6, "Level 1": 1}}, "fips_certlike": {"Certlike": {"HMAC-SHA-1": 32, "SHA256": 1, "SHA2-224": 52, "SHA2- 256": 6, "SHA2-384": 49, "SHA2- 512": 10, "SHA2-256": 61, "SHA2-512": 53, "SHA-1": 35, "SHA2- 224": 5, "SHA3-224": 3, "SHA3-256": 3, "SHA3-384": 3, "SHA3-512": 4, "SHA2- 384": 9, "SHA-1, 224": 3, "SHA- 1, 224": 1, "SHS 1780": 16, "SHA- 1": 1, "SHS #1780": 22, "SHA3": 1, "SHS#1780": 2, "SHA1": 1, "SHA-256": 2, "SHA-512": 2, "RSA 1024": 3, "PKCS 1": 5, "RSA PKCS 1": 1, "PKCS #1": 4, "PKCS#1": 4, "AES192": 1, "AES-GCM Encrypt/Decrypt; 128": 2, "AES 256": 2, "AES-CBC Encrypt/Decrypt; 128": 1, "AES-CTR Encrypt/Decrypt 128": 1, "AES-256": 2, "AES 128, 192": 1, "DES (192": 1, "# SHS": 11, "# C839": 1}}, "vendor": {}, "eval_facility": {}, "symmetric_crypto": {"AES_competition": {"AES": {"AES": 64, "AES192": 1, "AES-": 34, "AES-256": 2}, "CAST": {"CAST": 3}}, "DES": {"DES": {"DES": 22}, "3DES": {"TDES": 8, "Triple-DES": 30}}, "constructions": {"MAC": {"HMAC": 29, "CMAC": 13}}}, "asymmetric_crypto": {"RSA": {"RSA 1024": 3}, "ECC": {"ECDH": {"ECDH": 22}, "ECDSA": {"ECDSA": 79}, "ECC": {"ECC": 15}}, "FF": {"DH": {"Diffie-Hellman": 1, "DH": 6}, "DSA": {"DSA": 45}}}, "pq_crypto": {}, "hash_function": {"SHA": {"SHA1": {"SHA-1": 39, "SHA1": 1}, "SHA2": {"SHA256": 1, "SHA-256": 2, "SHA-512": 2}, "SHA3": {"SHA3-224": 3, "SHA3-256": 3, "SHA3-384": 3, "SHA3-512": 4, "SHA3": 1}}, "MD": {"MD5": {"MD5": 1}}, "PBKDF": {"PBKDF": 12}}, "crypto_scheme": {"MAC": {"MAC": 30}, "KA": {"Key agreement": 7, "Key Agreement": 1}}, "crypto_protocol": {"SSH": {"SSH": 1}, "TLS": {"SSL": {"SSL": 4}, "TLS": {"TLS": 43, "TLS v1.2": 1, "TLS 1.2": 3, "TLSv1.0": 2}}}, "randomness": {"PRNG": {"DRBG": 123}, "RNG": {"RBG": 7}}, "cipher_mode": {"ECB": {"ECB": 3}, "CBC": {"CBC": 7}, "CTR": {"CTR": 1}, "GCM": {"GCM": 10}}, "ecc_curve": {"NIST": {"P-521": 40, "P-224": 41, "P-256": 46, "P-384": 32, "P-192": 6, "K-233": 8, "K-283": 8, "K-409": 8, "K-571": 7, "B-233": 8, "B-409": 4, "B-571": 8, "B-283": 5, "B-163": 1}, "Brainpool": {"brainpoolP224r1": 2, "brainpoolP256r1": 2, "brainpoolP320r1": 2, "brainpoolP384r1": 2, "brainpoolP512r1": 2, "brainpoolP160r1": 1}, "ANSSI": {"FRP256v1": 3}, "Curve": {"Curve25519": 1}}, "crypto_engine": {}, "tls_cipher_suite": {"TLS": {"TLS_ECDHE_RSA_WITH_AES_128_GCM_SHA256": 2, "TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384": 2, "TLS_ECDH_RSA_WITH_AES_128_CBC_SHA256": 1, "TLS_ECDH_RSA_WITH_AES_256_CBC_SHA384": 1, "TLS_ECDH_RSA_WITH_AES_128_GCM_SHA256": 1, "TLS_ECDH_RSA_WITH_AES_256_GCM_SHA384": 1, "TLS_ECDH_ECDSA_WITH_AES_128_CBC_SHA256": 1, "TLS_ECDH_ECDSA_WITH_AES_256_CBC_SHA384": 1, "TLS_ECDH_ECDSA_WITH_AES_128_GCM_SHA256": 1, "TLS_ECDH_ECDSA_WITH_AES_256_GCM_SHA384": 1, "TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256": 1, "TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384": 1, "TLS_ECDHE_ECDSA_WITH_AES_128_CBC_SHA256": 1, "TLS_ECDHE_ECDSA_WITH_AES_256_CBC_SHA384": 1, "TLS_ECDHE_ECDSA_WITH_AES_128_GCM_SHA256": 1, "TLS_ECDHE_ECDSA_WITH_AES_256_GCM_SHA384": 1}}, "crypto_library": {"OpenSSL": {"OpenSSL": 16}}, "vulnerability": {}, "side_channel_analysis": {"FI": {"physical tampering": 1}}, "device_model": {}, "tee_name": {"AMD": {"PSP": 2}, "IBM": {"SSC": 14}}, "os_name": {}, "cplc_data": {}, "ic_data_group": {}, "standard_id": {"FIPS": {"FIPS 140-3": 6, "FIPS 186-4": 158, "FIPS 202": 13, "FIPS 180-4": 112, "FIPS 198-1": 55, "FIPS PUB 186-4": 1, "FIPS PUB 140-3": 2}, "NIST": {"SP 800-38B": 8, "SP 800-108": 27, "SP 800-38D": 29, "SP 800-38F": 28, "SP 800-56B": 1, "SP 800-90B": 4, "SP 800-90A": 1, "SP 800-132": 8, "SP 800-52": 1, "SP 800-38A": 31, "SP 800-38C": 4, "SP 800-38G": 1}, "PKCS": {"PKCS 1": 3, "PKCS #1": 2, "PKCS#1": 2}, "RFC": {"RFC 5288": 2}, "ISO": {"ISO/IEC 24759": 2}}, "javacard_version": {}, "javacard_api_const": {}, "javacard_packages": {}, "certification_process": {"OutOfScope": {"out of scope": 1, "HSM. The LiquidSecurity Appliance is outside the module\u2019s cryptographic boundary and therefore out of scope of this validation. CNN35XX-NFBE-G Firmware: CNN35XX-NFBE-FW-2.09-0702 CNN35XX-NFBE-G Secure": 1}}}, "policy_metadata": {"pdf_file_size_bytes": 2536943, "pdf_is_encrypted": false, "pdf_number_of_pages": 119, "/CreationDate": "D:20260310121952-04'00'", "/ModDate": "D:20260310121952-04'00'", "pdf_hyperlinks": {"_type": "Set", "elements": []}}}, "heuristics": {"_type": "sec_certs.sample.fips.FIPSCertificate.Heuristics", "algorithms": {"_type": "Set", "elements": ["DSA SigVer (FIPS186-4)C823", "HMAC-SHA2-256C839", "KAS-ECC Sp800-56Ar3A1219", "KDA OneStep Sp800-56Cr1A1192", "HMAC-SHA2-512C839", "DSA SigGen (FIPS186-4)C823", "KDA TwoStep Sp800-56Cr1A1192", "SHA-1SHS 1780", "RSA SigVer (FIPS186-4)C824", "KAS-ECC CDH-ComponentC829", "SHA2-224SHS 1780", "AES-CTRC839", "KTS-IFCA1194", "SHAKE-256A1197", "ECDSA KeyGen (FIPS186-4)C825", "SHA2-384SHS 1780", "RSA Decryption PrimitiveC839", "ECDSA SigGen (FIPS186-4)C829", "DSA KeyGen (FIPS186-4)C823", "KDA HKDF Sp800-56Cr1A1192", "KDF TLSC840", "AES-GMACC839", "SHA3-224A1197", "DSA PQGGen (FIPS186-4)C823", "Counter DRBGC821", "DSA PQGVer (FIPS186-4)C823", "SHA3-256A1197", "RSA Signature PrimitiveC839", "TDES-ECBTDES 1311", "RSA SigGen (FIPS186-4)A1199", "SHAKE-128A1197", "ECDSA KeyVer (FIPS186-4)C825", "TDES-KWC1263", "AES-CMACC839", "SHA2-256SHS 1780", "AES-GCMC839", "KAS-IFC-SSCA1193", "KDF SP800-108C839", "RSA KeyGen (FIPS186-4)C824", "RSA SigGen (FIPS186-2)C824", "ECDSA SigVer (FIPS186-4)C829", "HMAC-SHA2-224C839", "AES-CCMC839", "SHA3-512A1197", "SHA2-512SHS 1780", "AES-KWC1263", "KAS-ECC-SSC Sp800-56Ar3A2161", "AES-KWPC1263", "KDF ANS 9.63C825", "AES-CBCC839", "HMAC-SHA-1C839", "Hash DRBGC830", "AES-ECBC839", "TDES-CBCTDES 1311", "PBKDFA1196", "HMAC-SHA2-384C839"]}, "extracted_versions": {"_type": "Set", "elements": ["2.09", "4.03", "1.0", "2.0", "3.0"]}, "cpe_matches": null, "verified_cpe_matches": null, "related_cves": null, "policy_prunned_references": {"_type": "Set", "elements": ["1311"]}, "module_prunned_references": {"_type": "Set", "elements": []}, "policy_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": {"_type": "Set", "elements": ["1311"]}, "indirectly_referencing": {"_type": "Set", "elements": ["1311"]}}, "module_processed_references": {"_type": "sec_certs.sample.certificate.References", "directly_referenced_by": null, "indirectly_referenced_by": null, "directly_referencing": null, "indirectly_referencing": null}, "direct_transitive_cves": null, "indirect_transitive_cves": null}, "state": {"_type": "sec_certs.sample.fips.InternalState", "module": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": null, "txt_hash": null, "json_hash": null}, "policy": {"_type": "sec_certs.sample.document_state.DocumentState", "download_ok": true, "convert_ok": true, "extract_ok": true, "source_hash": "f87737775e661f03978a75777c849414e5aa2667b30655d5c46465af50171b93", "txt_hash": "2f3458954c41ccc951fde162767ebbfd6d54858c7961419144fccec7fc5f0371", "json_hash": null}}}